package xin.yangshuai.xss01.controller;

import org.springframework.stereotype.Controller;
import org.springframework.ui.ModelMap;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.ResponseBody;

import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpSession;

/**
 * IndexController
 *
 * @author shuai
 * @date 2021/10/29
 */
@Controller
public class IndexController {

    @RequestMapping({"index", "/"})
    public String index(String info,ModelMap modelMap) {
        modelMap.put("info", info);
        return "index";
    }

    @RequestMapping("info")
    @ResponseBody
    public String info(HttpServletRequest request) {
        HttpSession session = request.getSession();
        return "<script>alert(hello world !)</script>";
    }
}
